Re: [pfSense] WHY: SSL/TLS Diffie-Hellman Modulus = 1024 Bits (Logjam)

2015-08-20 Thread Claudio Thomas
on another (faster) system and then copy the file to the pfsense host. The once generated DH parameters (in the file) will than be simply used on the pfsense host. Best regards, Claudio Thomas -- Working on OpenWrt CC for Xmodus GSM Router XM1710E http://www.xmodus-systems.de/openwrt

Re: [pfSense] How do I harden my pfsense install WRT TLS and ssh?

2015-07-29 Thread Claudio Thomas
On 29.07.2015 18:02, Vick Khera wrote: On Tue, Jul 28, 2015 at 4:12 PM, Moshe Katz mo...@ymkatz.net wrote: Again, I agree with you that this shouldn't affect your score. I am simply explaining why they do it. based on this explanation, i agree. there's no reason for them to demand your

[pfSense] pfSense 2.2 upgrade experiences

2015-02-09 Thread Claudio Thomas
Hi, at first: thanks for the great work! 1) After trying to update my pfSense 2.1.5 (i386) to 2.2 over web-interface it reboots as expected... But this was all. The firewall was not working anymore. After a while inspecting the problem I fixed the config, so that it seems to run again. Now I've

Re: [pfSense] pfSense 2.2 upgrade experiences

2015-02-09 Thread Claudio Thomas
On 09.02.2015 10:20, J. Echter wrote: Am 09.02.2015 um 09:53 schrieb Claudio Thomas: Hi, at first: thanks for the great work! 1) After trying to update my pfSense 2.1.5 (i386) to 2.2 over web-interface it reboots as expected... But this was all. The firewall was not working anymore. After

Re: [pfSense] confirmation: pfSense 2.0+IPSec Xauth PSK+Android 4.2.2/4.3 works

2013-09-11 Thread Claudio Thomas
11:26 AM, Adam Thompson wrote: Updated. Thank you for the confirmation! -Adam Thompson athom...@athompso.net mailto:athom...@athompso.net *From:*list-boun...@lists.pfsense.org [mailto:list-boun...@lists.pfsense.org] *On Behalf Of *Claudio Thomas *Sent:* Tuesday, September 10

[pfSense] confirmation: pfSense 2.0+IPSec Xauth PSK+Android 4.2.2/4.3 works

2013-09-10 Thread Claudio Thomas
Hi, in the summary of http://doc.pfsense.org/index.php/Android_VPN_Connectivity; the connectivity for Android 4.2 and 4.3 (Jelly Bean) is missing. If've already successful tested them: - pfSense 2.0.03/IPSec Xauth PSK for 4.2.2 = Yes, works - pfSense 2.0.03/IPSec Xauth PSK for 4.3 = Yes, works

Re: [pfSense] IPSec connection without default-route

2013-03-02 Thread Claudio Thomas
/wiki/Split_tunneling Am 13.02.13 14:30 schrieb Claudio Thomas unter claudio.tho...@ezi.de: Hi, sorry for my rerequest. Is there a way to set up an IPsec connection without routing all the client-traffic thrue the pfSense router? In my case the client is setting a route add 0.0.0.0 netmask

Re: [pfSense] IPSec connection without default-route

2013-02-13 Thread Claudio Thomas
192.168.150.0 netmask 255.255.255.0 gw ipsec-connection-ip. Best regards, Claudio Am 06.02.2013 11:25, schrieb Claudio Thomas: Hi, actually when connecting via IPSec from Client (A) to pfSense 2.02 (B) all traffic from A is routed to B. Actual routing look like: Client ApfSense B

[pfSense] IPSec connection without default-route

2013-02-06 Thread Claudio Thomas
Hi, actually when connecting via IPSec from Client (A) to pfSense 2.02 (B) all traffic from A is routed to B. Actual routing look like: Client ApfSense BNetwork 10.8.0.5/32 - 10.8.0.1/24 192.168.150.0/24 |

[pfSense] confirmation: pfSense 2.0+IPSec Xauth PSK+Android 4.1 works

2013-02-04 Thread Claudio Thomas
Hi, in the summary of http://doc.pfsense.org/index.php/Android_VPN_Connectivity; the connectivity of pfSense 2.0/IPSec Xauth PSK ist marked with probably for Android 4.1 (Jelly Bean) In the same article there is written that testing is needed to confirm. Thats what I whant to do, to confirm :-)